Currently the provision code derives the DNS domainname from the Kerberos realm. The patch attached to this bug adds the option --dnsdomain to the provision code, allowing DNS domains to differ from the Kerbeos realm. Maybe additional places need to be fixed to complete this.

The fact that the DNS name and realm are connected is at the very heart of active directory. Much more than this would need to be changed to permit this disconnection.
How would such a realm interact with Microsoft's implementation?
Why are you proposing this change?
I simply can't see how this can be made to work